QID 997367
Date Published: 2024-02-20
QID 997367: Java (Maven) Security Update for com.liferay.portal:release.dxp.bom (GHSA-2mx7-xvfg-fg53)
Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-2mx7-xvfg-fg53 for updates and patch information.
Vendor References
- GHSA-2mx7-xvfg-fg53 -
github.com/advisories/GHSA-2mx7-xvfg-fg53
CVEs related to QID 997367
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2mx7-xvfg-fg53 | com.liferay.portal:release.dxp.bom |
|